
Certified Tester Security Test Engineer
Domain 9Objective 2
Black-Box Security Test Tools CT-STE Practice Questions (Page 4)
Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
Questions 16–20
- 16
A security team is asked to assess a legacy on-premises application that exposes a proprietary binary protocol on TCP port 8443. The team has a two-day window and no access to source code or design documents. They need to identify protocol-level parsing flaws that could lead to memory corruption. Which tool category should they prioritize?
Select an answer first - 17
A QA engineer is testing a new REST API that accepts JSON payloads. They want to automate the discovery of injection flaws and schema-validation weaknesses in the API endpoints. The team has a CI/CD pipeline and needs a tool that can be integrated into the build process. Which approach best fits the requirement?
Select an answer first - 18
Which of the following is a category of black-box security test tools?
Select an answer first - 19
A security team is assessing a web application that is behind a Web Application Firewall (WAF). The vulnerability scanner reports no findings. The team suspects the WAF is blocking the scanner's payloads. What is the most appropriate action?
Select an answer first - 20
What is a primary use case for vulnerability scanners in black-box testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.